Take your IAM global
Fully isolate identity profile data with InCountry’s Sovereign Identity

Secure digital twins fully isolate identity profiles within a country
- Avoid regulatory barriers and cost of cross-border data transfers
- Simpler and more efficient than federating multiple orgs
- Available globally beyond your identity vendor’s regions
- Works with both Customer and Workforce identity

A new model for customer data protection
- Store all PII, PHI, and PFI in its country of origin to avoid cross-border regulatory burden
- Store cloaked profiles in your global Customer Identity and Access Management system (CIAM)
- Customer services and sales teams in each country or regulatory area can access uncloaked data
InCountry’s comprehensive solution for IAM and CIAM data residency
Digital Twins
Profile data is securely managed and isolated within a country.
Dialogs
Cloaks and uncloaks identity fields in registration, login, profile, and other forms.
Authorization
Cloaks and uncloaks claims in JWT authorization tokens.
MFA
Multi-factor authorization via email and SMS with cloaked emails and phone numbers.
APIs
Requires no code changes with SCIM 2.0 and vendor API cloaking and uncloaking of fields.
Admin
Fully integrated so only admins within a country can see uncloaked data and manage users and groups.


Fully compatible with existing identity APIs
- SCIM 2.0 support
- Vendor API support including Okta Workforce, Okta Auth0, WSO2 Asgardeo, and Strivacity.
- JWT tokens are augmented with local claims
- Access to individual records and fields continues to be controlled by the Identity Access Management system and source application’s policies
- Seamlessly cloak and uncloak JWT claims for MCP and A2A AI agents
- Cloak and uncloak MCP and A2A payloads governed by identity context
- Comply with EU AI Act and other data minimization requirements
- Support cross-border Sovereign AI with data leak prevention of identity claims
Support cross-border Sovereign AI and AI data protection with claims cloaking

Flexible deployment options to meet every enterprise requirement
InCountry multi-tenant is highly scalable with failover and is available in numerous countries
InCountry single-tenant can be deployed on any cloud including AWS, Microsoft Azure, Google Cloud, Oracle Cloud, and Alibaba Cloud
AWS Outposts offers servers and racks that can be deployed anywhere and managed with the AWS Console
On-premises on any cloud for full data sovereignty requires two hosts for the application and the database

The enterprise-grade solution for data protection
Enterprise-Ready
- SaaS, single-tenant anywhere, AWS Outposts, and Sovereign Cloud deployment
- Two points-of-presence with active-active failover
- Guaranteed messaging across unpredictable networks
Developer-Friendly
- Invoke via MCP Proxy, MCP Tool, Web Service Proxy, REST API, or CLI
- Use as skill in Claude Code, OpenCode, Grok Build, OpenAI Codex, and other coding agents
- Cloak data with generalization, tokenization, hashing, and masking strategies
Bank-Grade Security
- Granular policy-based authorization combined with fine-grained authorization from data sources
- Granular policy-based authorization combined with fine-grained authorization from data sources
- Searchable encryption using NIST standards
Global Compliance
- Data leak prevention across borders and data minimization within brders
- Detailed support for regulatory approval in complex jurisdictions
- Full observability with detailed logging and OpenTelemetry dispatch